HackingStolen CredentialsTargetedData ExfiltratedIDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNTLowResolved
IHS Inc.
bd_8484b6c3e6e8b7aa · schema v1 · pii pii-v1
Full breach record for IHS Inc. →IHS Inc, a payment processing subsidiary, notified customers of a cyber attack where unauthorized parties accessed databases containing names, contact info, usernames, passwords, and payment card numbers. The incident was discovered in Feb 2013, affecting data accessed around Nov 2012. IHS engaged law enforcement and forensic experts, reset passwords, and enhanced security safeguards.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-41789
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2013
- Raw hash
- 37c70939bcf55c4b367d04e241cd1a9762af59468b139db65dd4d36f102aca95
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- IHS Inc.norm: ihs
- Domain
- ihserc.com
Incident
- Discovered
- Feb 22, 2013
- Materiality determined
- May 15, 2013
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(82 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.